CVE-2026-83548
Description
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.
Summary dbcve.org
A pre-authentication Server-Side Request Forgery (SSRF) vulnerability exists in the SMA1000 Appliance Work Place interface. The flaw stems from an unintended alternate access path that allows remote unauthenticated attackers to make the appliance perform arbitrary HTTP requests to internal or external resources, potentially exposing sensitive internal functionality and enabling further unauthorized operations.
Mitigation
Apply vendor-supplied patches for SMA1000 to remediate the alternate access path; if no patch is available, restrict network access to the Work Place interface using firewall rules or disable untrusted access paths until a fix is deployed.